Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » Windows » How to find out who restarted Windows Server
  • Delete Edit or Revert a Snapshot on vSphere
    Manage VMware Snapshots: Delete or Edit or Revert a Snapshot Virtualization
  • Slide2
    How to Setup Jenkins Pipelines Environment for Docker Container Deployment Containers
  • the remote procedure call failed
    Error 0xc1420117: The directory could not be completely unmounted Windows Server
  • Synology Diskstaion update to latest version 7.3
    Download and update Synology DiskStation NAS to DSM 7.3 Storage
  • wacxx
    Install Windows Admin Center in an unattended mode using a self-signed certificate Windows
  • downloadzoom recording
    How to download a shared ZOOM recording JIRA|Confluence|Apps
  • lampstack feature lamp stack ubuntu
    How to Install LAMP Stack on Ubuntu 18.04 Linux
  • google chrome logo 2
    Set Google as default: How to set a browser as default in Windows 10 Windows

How to find out who restarted Windows Server

Posted on 27/10/202220/08/2024 Matthew By Matthew No Comments on How to find out who restarted Windows Server
Featured-image_new
Windows Server Event Log Viewer

If your organization has many system administrators, you may want to know who restarted the server at certain times. This post will show you How to find out who restarted Windows Server. This is to view shutdown/reboot/startup logs on Windows servers.

Windows has a great application called Windows Event Viewer that records all actions that occur on the computer.

The event log service, which is a Windows core service, manages the Windows Event Viewer. The event viewer records the event log service’s startup and shutdown history. It tracks each user’s activity while the machine is working. On the Windows Server/Desktop, and PCs, it logs errors, information messages, and warnings.

Here are other related guides on Windows Server: How to uninstall Internet Explorer from your Windows PC or Windows Server, How to install Windows Server 2022 on VirtualBox, How to Install Web Server IIS in Windows Server 2019, Network File System: How to install NFS Server on Windows Server, and how to Migrate Roles and Features to Windows Server 2022 using WSMT.

The Most Frequent Startup and Shutdown Events

There are several events associated with shutting down and restarting a Windows PC. However, in this post, we will show you the most common events:

  • Event ID 41: indicates that your Windows machine rebooted without completely shutting down.
  • Event ID 6005: This code indicates the starting of the event log service.
  • Event ID 1074: Your computer logs this event whenever a program makes your laptop restart or shut down. Additionally, this event lets you know when a user rebooted or shut down the machine using the Start menu or the CTRL+ALT+DEL keyboard shortcut.
  • Event ID 6006: If your Windows PC shuts down properly, this event is recorded.
  • Event ID 6008: This event occasionally appears in your system log when your machine abruptly or unexpectedly shuts down.
  • Event ID 6009: Identifies the name of the Windows product, version, build number, service pack number, and operating system type that is detected during boot.
  • Event ID 1076: Keeps track of the first time a user with shutdown permissions logs in to the computer after an unexpected restart or shutdown, along with a reason for the occurrence.

Please see how to detect if an application was uninstalled on Windows: Find out who has uninstalled an application via Windows Event Viewer, How to view Scheduled Events on AW using the Command Line (CLI), How to prevent a remote shutdown and restart in Windows, How to prevent users from shutting down in a Virtual Machine, and How to use command prompt to shutdown and restart your computer.

How to find out who restarted Windows Server

In this section, I will show you how to view Shutdown and Restart Log from Event Viewer. Let’s go over the whole process of getting this data from the Windows event viewer.

To open the Event Viewer, press Win + R to launch the Run dialog box and type eventvwr.

image0-1
Run dialog box

In the left pane, click on Windows Logs and select System. You’ll see a list of events that occurred while Windows was operating in the center pane. Click on the Event ID label to sort the data by the Event ID column.

image1-5
Event Viewer

If the event log is large, the sorting will fail. You can also make a filter using the Actions pane on the right. Simply choose “Filter current log.”

image2-3
Filtering the Event log

In the Event IDs field, enter 1074 or any Event ID. Under Logged, you can also choose a time period.

image3-3
Event log filter

After you have completed all of the procedures, the Windows Event Viewer will only show events connected to the shutdown.

How to View Shutdown and Restart Log Using Windows PowerShell

The PowerShell command Get-EventLog can be used to get the shutdown and reboot logs in Windows from the command line.

Enter the following command, for example, to filter the 10,000 most recent entries in the System Event Log:

Get-EventLog System -Newest 10000 | ` Where EventId -in 41,1074,1076,6005,6006,6008,6009,6013 | ` Format-Table TimeGenerated,EventId,UserName,Message -AutoSize -wrap

Run the following command to view just events related to Windows shutdowns and restarts:

Get-WinEvent -FilterHashtable @{logname = 'System'; id = 1074} | Format-Table -wrap

Query Via WMI

To query a remote device to get the last reboot time with Get-WmiObject

Get-WmiObject -ClassName win32_operatingsystem -ComputerName techdaPC2 | Select-Object csname, lastbootuptime

I hope you find this post helpful. If you have any questions, feel free to leave them in the comment section below.

5/5 - (1 vote)

Thank you for reading this post. Kindly share it with others.

  • Click to share on X (Opens in new window) X
  • Click to share on Reddit (Opens in new window) Reddit
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on Pinterest (Opens in new window) Pinterest
  • Click to share on Tumblr (Opens in new window) Tumblr
  • Click to share on Telegram (Opens in new window) Telegram
  • Click to share on WhatsApp (Opens in new window) WhatsApp
  • Click to share on Pocket (Opens in new window) Pocket
  • Click to share on Mastodon (Opens in new window) Mastodon
  • Click to share on Bluesky (Opens in new window) Bluesky
  • Click to share on Threads (Opens in new window) Threads
  • Click to share on Nextdoor (Opens in new window) Nextdoor
Windows, Windows Server Tags:Event Viewer, eventlog, Windows 10, Windows 11, Windows Server 2016

Post navigation

Previous Post: FoneTool is the best iPhone backup software
Next Post: Apache JMeter Load Testing: Test Mobile Apps on Windows

Related Posts

  • banner 3
    How to Enable or Disable SuperFetch in Windows 11 Windows
  • Feature image Audio settings
    Master Your Sound Experience: How to Manage Audio Settings on Windows 11 Windows
  • Windows 10 logo wmskill.com
    Handy Shutdown commands available in Windows Windows
  • change keyboard layout windows 10 thumb800
    How to use the On-Screen Keyboard Windows
  • banner
    Prevent Microsoft Edge from sending your Search data to Microsoft Windows
  • How to manage user permission in AD and Synology
    Manage User Permission on Synology with Active Directory [Part 1] Reviews

More Related Articles

banner 3 How to Enable or Disable SuperFetch in Windows 11 Windows
Feature image Audio settings Master Your Sound Experience: How to Manage Audio Settings on Windows 11 Windows
Windows 10 logo wmskill.com Handy Shutdown commands available in Windows Windows
change keyboard layout windows 10 thumb800 How to use the On-Screen Keyboard Windows
banner Prevent Microsoft Edge from sending your Search data to Microsoft Windows
How to manage user permission in AD and Synology Manage User Permission on Synology with Active Directory [Part 1] Reviews

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

sysadmin top30a

  • Delete Edit or Revert a Snapshot on vSphere
    Manage VMware Snapshots: Delete or Edit or Revert a Snapshot Virtualization
  • Slide2
    How to Setup Jenkins Pipelines Environment for Docker Container Deployment Containers
  • the remote procedure call failed
    Error 0xc1420117: The directory could not be completely unmounted Windows Server
  • Synology Diskstaion update to latest version 7.3
    Download and update Synology DiskStation NAS to DSM 7.3 Storage
  • wacxx
    Install Windows Admin Center in an unattended mode using a self-signed certificate Windows
  • downloadzoom recording
    How to download a shared ZOOM recording JIRA|Confluence|Apps
  • lampstack feature lamp stack ubuntu
    How to Install LAMP Stack on Ubuntu 18.04 Linux
  • google chrome logo 2
    Set Google as default: How to set a browser as default in Windows 10 Windows

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,836 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

Active Directory AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.